Data Processing Agreement
Standard terms under GDPR Article 28 for clients whose customers talk to an ApexWeb chatbot or phone receptionist.
1. Parties
Controller: the client who ordered the service. Processor: Tokár Ádám, sole trader, trading as ApexWeb, Szőlős utca 4/1, 5700 Gyula, Hungary, tax number 92003747-1-24, info@apexweb.hu.
2. Subject and duration
The processor runs an AI chatbot and/or AI phone receptionist for the controller. This agreement lasts as long as the subscription.
3. Nature and purpose
- Answering the controller's customers in chat and on the phone.
- Recording leads, bookings and messages for the controller.
- Keeping conversation logs for quality checks and fixing errors.
The processor does not use the data for its own purposes.
4. Data subjects and data
The controller's customers and prospects who use the chat or call. Data: name, phone, email, message content, call transcripts and timestamps. Special categories, such as health data, are processed only with the controller's written instruction.
5. Instructions and confidentiality
The processor acts only on the controller's documented instructions and tells the controller if an instruction seems unlawful. Everyone with access is bound by confidentiality.
6. Security
- Encryption in transit (TLS 1.2 or higher) and at rest on the platforms used.
- Access only for those who need it.
- Logging of access and processing events.
- Regular updates and security reviews.
7. Sub-processors
The controller gives general authorisation for these sub-processors and is told in advance of any change, with the right to object:
- Supabase: database, EU (Frankfurt).
- OpenAI: language model, USA, SCC and DPF.
- Vapi: call handling, USA, SCC.
- ElevenLabs: voice synthesis, USA, SCC.
- Telnyx: telephony, USA and EU, SCC.
- Soniox: speech to text, USA, SCC.
- Resend: email notifications, USA and EU, SCC.
- Netlify: hosting, USA, SCC.
- Stripe: payments, USA and EU, SCC and DPF.
8. Assistance, breaches and audits
The processor helps the controller answer data subject requests and forwards any request it receives. It reports a personal data breach without undue delay, with the information the controller needs for its 72-hour notification. The controller may audit the processor with 10 business days' notice.
9. End of processing
When the service ends, the processor deletes or returns the data at the controller's choice and confirms this in writing, unless the law requires retention.
10. Transfers and law
Transfers outside the EEA rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework. This agreement is governed by Hungarian law and the GDPR.